Security & Data

Where your information lives, and what happens to it

The same rules apply across HeyMi and Data Mi: hosted and processed in Australia, never used to train external models, owned by you. Below is the detail, written so you can check it rather than take it on trust.

SydneyPrivate cloud

HeyMi

Where it runs, and who can see what

HeyMi is hosted within Mattingly’s private cloud environment on AWS infrastructure in Sydney.

Hosting and processing

Hosted in Sydney, Australia
Your data is stored in Australia
Your data does not leave Australia
Processing happens inside Mattingly’s private cloud environment
Models are hosted by Mattingly, not called from an external AI service
Backups are held in Australia

Control and ownership

You own your data
Your data is never used to train AI models
Your data can be deleted on request
Access is controlled by user, group and role
Two people can be permitted to see different information
Encrypted in transit and encrypted at rest
You control how long conversation history is kept
Optional administrator logging and audit trail
HeyMi responds and recommends. It does not act inside your systems on its own.

Data Mi

Working data, handled the same way

Data Mi engagements often involve the most sensitive information in a business — customer records, pricing, contracts. The handling rules are stated up front and written into the engagement.

Your data is processed in Australia
Working data is held in Mattingly’s private cloud environment
Transfers use encrypted methods including HTTPS and SFTP
You control how long anything is retained
Your data is not sent to external AI services
Source and intermediate files are deleted on schedule or on request

What we do not claim

Mattingly does not hold a formal information security certification today. We are working towards one, and we would rather say that plainly than imply otherwise. We are also not going to imply one with a badge or a phrase like “bank-grade”. When the certification is in place, this page will say so and name the standard.

Questions

Data and residency, answered

HeyMi is hosted within Mattingly’s private cloud environment on AWS infrastructure in Sydney. Your data is stored in Australia, processed in Australia and backed up in Australia. It does not leave Australia, and it is not sent to public or external AI models.

You do. You own your data. Access inside your business is controlled by user, group and role. You control how long conversation history is kept, and your data can be deleted on request.

No. Customer information is not used to train AI models, and it is not sent to public or external AI services. Your data is not our training data.

Data Mi processes customer data in Australia within Mattingly’s private cloud environment. Transfers use encrypted methods including HTTPS and SFTP, retention is controlled by you, source and intermediate files are deleted on schedule or on request, and no customer data is sent to external AI services.

Mattingly does not hold a formal information security certification today. We are working towards one, and we would rather say that plainly than imply otherwise.

No. None of them. HeyMi runs models that Mattingly hosts and operates inside its own environment in Sydney. Your questions and your data are not sent to OpenAI, Anthropic, Google, AWS Bedrock or any other external AI provider’s API. AWS provides the underlying infrastructure, the same way it would for any Australian-hosted application, but no external AI service sits in the path of your question.

No. HeyMi responds and recommends. It does not autonomously take actions in your business systems, which means a person is always between the recommendation and the consequence.

Talk to us

Send us your security questionnaire. We’ll fill it in

Including the questions where the honest answer is no. That is usually more useful to your risk register than a page of assurances.